TrendingTopic

Vibe coding increasing supply chain risk

March 31, 2026Gergely Orosz, Deedy, @levelsio

Gergely Orosz and Deedy highlight rising supply chain attacks, with Deedy tying the axios, litellm, and xz incidents to "vibecoding" where developers don’t understand dependencies they ship.

Supply chain attacks are becoming more frequent, and far more serious.
Supply chain attacks like the currently breaking axios, litellm and xz
only going to be more commonplace in the vibecoding world
The entire premise of vibecoding is “I don’t need to understand the code”
I think I'll just vibe code all my Chrome extensions with Claude Code
to avoid having to use any and being dependent on someone getting bribed to add malware to their extension
It's not a question IF it happens, just WHEN
Gergely Orosz
Deedy
@levelsio
securitydependenciesdevtoolsclaude codevibe coding

See what experts are saying right now

This finding is one of many signals tracked across Artificial Intelligence. The live feed updates every few hours with new expert voices, debates, and emerging ideas.

← Back to Artificial Intelligence